The issue was reported from hosts using Clouflare WordPress managed rules.
Ray ID reveals this Yoast SEO related CVE.
Digging deeper the "orderby" field in the form (primary ordering option) triggers this rule - even though intgerestingly the value does not match and are inconsistent.
Renaming the option to "primary_orderby" could resolve the issue.